Files
LangBot/web/src
RockChinQ 3b5e89f17f feat(box): SaaS guard to force a single global sandbox scope
Add system.limitation.force_box_session_id_template: when non-empty it
overrides every pipeline's box-session-id-template at resolve time, pinning
all queries to one shared sandbox (e.g. {global}). This is the authoritative,
unbypassable guard — it runs on every exec call, so editing the pipeline
config via API cannot escape it. The web UI locks the Sandbox Scope selector
via a combined box_scope_editable flag (box available AND not forced).
2026-06-08 06:38:52 -04:00
..
2026-06-03 11:12:39 +08:00
2025-05-10 01:19:30 +08:00
2026-03-28 15:50:32 +08:00